CVE-2008-2812

The Linux kernel before 2.6.25.10 does not properly perform tty operations, which allows local users to cause a denial of service (system crash) or possibly gain privileges via vectors involving NULL pointer dereference of function pointers in (1) hamradio/6pack.c, (2) hamradio/mkiss.c, (3) irda/irtty-sir.c, (4) ppp_async.c, (5) ppp_synctty.c, (6) slip.c, (7) wan/x25_asy.c, and (8) wireless/strip.c in drivers/net/.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 16%
VendorProductVersion
linuxlinux_kernel
𝑥
< 2.6.25.10
canonicalubuntu_linux
6.06
canonicalubuntu_linux
7.04
canonicalubuntu_linux
7.10
canonicalubuntu_linux
8.04
opensuseopensuse
10.3
opensuseopensuse
11.0
debiandebian_linux
4.0
avayacommunication_manager
3.1 ≤
avayaexpanded_meet-me_conferencing
*
avayaintuity_audix_lx
2.0
avayameeting_exchange
5.0
avayamessage_networking
3.1
avayamessaging_storage_server
4.0
avayaproactive_contact
4.0
avayasip_enablement_services
-
avayasip_enablement_services
4.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
linux
intrepid
not-affected
hardy
Fixed 2.6.24-19.41
released
gutsy
dne
feisty
dne
dapper
dne
linux-source-2.6.15
intrepid
dne
hardy
dne
gutsy
dne
feisty
dne
dapper
Fixed 2.6.15-52.71
released
linux-source-2.6.20
intrepid
dne
hardy
dne
gutsy
dne
feisty
Fixed 2.6.20-17.39
released
dapper
dne
linux-source-2.6.22
intrepid
dne
hardy
dne
gutsy
Fixed 2.6.22-15.58
released
feisty
dne
dapper
dne
References